Showing posts with label Stage Fright Leak. Show all posts
Showing posts with label Stage Fright Leak. Show all posts

Thursday, 5 November 2015

Free App Scans Android Devices For Vulnerabilities


An American company has developed a free open source app that scans Android devices for vulnerabilities. According NowSecure it often happens that manufacturers do sometimes months to close serious security holes like Stage Fright in their version of Android.

Vulnerabilities can be present in many parts of Android. In the case of vulnerabilities in the kernel, according NowSecure difficult to control this without causing system instability. Something in the Android Vulnerability Test Suite account is held with. The app scans on several major vulnerabilities. All data while keeping within the device and be shared with anyone.Also, the source code of the app via Google Play is available for download at GitHub to see.

Wednesday, 4 November 2015

Critical Android Leak Fixes In Nexus Devices



During the patch cycle is from November Google poem multiple critical vulnerabilities in the Android version of Nexus devices, allowing an attacker to execute remote code on smartphones and tablets. Just as Microsoft is also Google each month with security updates.

It is in this case for updates to Nexus devices. The updates November fix seven vulnerabilities, two of which are labeled as critical. Through Critical vulnerabilities an attacker could execute code remotely on the device, for example by sending an MMS message, or if the user opens an e-mail or website. These are two leaks in the media server and libutils. The remaining five vulnerabilities, including one in the Stage Fright library, have a lesser impact.

According to Google, Android has several security measures that reduce the likelihood that Android leaks can be attacked successfully. For example, there are anti-exploit measures added to newer versions Android. In addition, search the Android Security Team via Verify Apps and SafetyNet to potentially harmful applications. Further send Google Hangouts, and Messenger will not automatically media to processes such as media server.

Updates are over-the-air (OTA) offered and are also available as firmware download. When the updates for the Android handsets from other manufacturers appear is unknown.

Tuesday, 18 August 2015

Android Again Hit By Leak In Media Server


Researchers have discovered a vulnerability in the media server of Android again, the same part where previously several other vulnerabilities were found, including severe Stage Fright leak . Through the latest vulnerability an attacker can execute arbitrary code on the device with the media rights server.

Thus, an attacker can take photos, create videos and previously made videos. The problem is present in Android 2.3 to 5.1.1, which represents almost all Android devices in circulation. To be attacked, the user must first install a malicious app via the vulnerability. This app does not require any permission, which can give users a false sense of security. Once activated an attacker could execute arbitrary code with the rights of media server.

The media server is involved in all kinds of media-related tasks, such as taking pictures, reading MP4 files and recording videos. "This allows the user privacy at risk", says Wish Wu of the Japanese anti-virus company Trend Micro discovered that the vulnerability. The virus fighter warned Google on June 19 that the leak as "high severity" labeled. On August 1, Google has published a patch for the Android Open Source Project (AOSP), but it is unclear if the update has already among users and suppliers is spread.

Friday, 7 August 2015

T-Mobile Temporarily Stopped Due MMS Stage Fright Leak


T-Mobile has temporarily stopped supporting MMS messages because of the Stage Fright leak , so the telco through its own forum disclosed. Stage Fright allows attackers via a single MMS message execute malicious code on Android devices. Although no attacks have been observed in the wild yet, T-Mobile has decided after a risk analysis to the "legacy mode" for MMS to turn.

This means that customers no longer received directly into their messaging app, the MMS media content. Instead, they receive an SMS notification containing a web link and a password to view the contents of the MMS message via a separate web portal. T-Mobile is warning customers that the risk remains that an MMS message is infected with the "Stage Fright virus". Customers with their Android smartphone to view the message in the web portal run thus still a risk of getting infected.

"Basically, this provides no real protection you but we thus avoid the risk of an even greater tragedy with a super-fast distribution and prolonged '' know ping-pong" effect ", let the provider. However, an employee reported that the technical department and the central MMS provider T-Mobile possibly next week come up with better alternatives to the measure. "If that is a fact, then I leave to return to the service in normal mode," said employee ' Mark K . Some customers are not very happy that they are not informed in advance about the measure because the MMS service suddenly stopped working. 

Wednesday, 5 August 2015

New Android Devices Leak Late Restart Endlessly


Researchers have discovered a new vulnerability in Android which could allow an attacker to restart the unit. In the event it is attacked leak via an app, it is possible to restart to endlessly leave the device. The problem is in the media server of Android, which also previously the Stage Fright leak was discovered, and a vulnerability that sets almost unusable makes.

Also this leak was from the Japanese anti-virus company Trend Micro detected and is present in Android 4.0.1 to 5.1.1 Lollipop. That equates to 89% of Android users. To carry out the attack must play a user to a malicious website an MKV file or install an app that contains the file. In the case of the attack on a media server app is running will end up in an endless loop. The system will eventually be so slow that the system will reboot or the battery expires.

If the attack performed via a website, a user must first play the movie itself. The impact can be especially great when a malicious app. The app can set that starts right at the loading of Android and can then leave as endless reboot the device. In this case, users are not able to remove the app in question, unless the product is launched in Safe mode.

The problem was reported to Google on May 19. On July 31, the Android security team said that there was a security update available. In many cases, Android users for updates depending on their phone company or the manufacturer of their device.Thus it may take longer for updates to be rolled out to users. To our knowledge, the vulnerability is not attacked in the "wild".

Tuesday, 4 August 2015

Attack On Very Serious Android Leak Nearly Public



On a Chinese forum has published information about how a very serious flaw in Android can be used to attack millions of Android phones via only a single MMS message, although the vulnerability also through apps and websites exploit. Reported security Zimperium.

Zimperium discovered the vulnerability, which called Stage Fright got. Later it turned out that anti-virus company Trend Micro same vulnerability was independently discovered . According Zimperium the problem affects 950 million Android devices. It is estimated that in 50% of the sensitive devices the attack without any user interaction to perform. In other cases, opening an MMS sufficient.

Right

The attack an attacker could execute arbitrary code with system privileges or media on the device. Thus, an attacker could take complete control of the camera and microphone, for example, to monitor users. On some handsets running the vulnerable software that is attacked via the MMS message with system privileges. In this case, an attacker elevated privileges and can do almost anything on the device that the user can. Zimperium argues that this is, however, "some" equipment. An attacker could execute arbitrary code on a device, even if the media rights, then may however try to increase his rights.

Originally publish at the Black Hat security conference in Las Vegas this week an exploit. Several organizations asked Zimperium to wait this. Something the company has agreed with it. The security updates for Android, however, are open source. Therefore, many researchers now work on an exploit to attack the vulnerability, reports the company. "We therefore believe that it is only a matter of time before we see attacks in the wild, assuming they do not already take place", said security researcher Zuk Avraham of Zimperium last Saturday knowing. This morning the company warned via Twitter that an exploit is now almost public.

Updates

The problem is that many Android users to update their phone company or the manufacturer of the device are dependent, instead of Google. Therefore it can take a long time updates ultimately be offered if the device is still supported. Several older Android models that are vulnerable and are no longer supported miss an important security measure. As a result, the impact on these devices is much greater.

It would total to about 60 million sets. According to Avraham, an attacker will create a network worm to send MMS messages.Together would the aircraft, after being infected, can send six billion MMS messages per day. Something that could have consequences for the network of telecom providers.

Actions

Users who want to protect themselves getting Zimperium the advice to keep the device up to date. In case the device is no longer supported, users on an operating system such as CyanogenMod switch that supports older devices longer. Another measure that can be taken is to disable automatic retrieval of MMS messages.

Thursday, 30 July 2015

New Android Phones Leak Is Virtually Useless



Researchers have discovered a vulnerability in Android devices allow an attacker can make it as good as useless. The vulnerability, which can be attacked through both websites as a rogue app, ensures that the user can not hear or see that there is a call or a text message is sent. Also, calls can not be accepted.

In case the attack is carried out via a malicious app can crash the operating system. When the app first set to start automatically upon loading the operating system, would thus arise a continuous loop of crashes. Each time the machine crashes because the user's phone and restart the app is loaded again and release Android then crash. Further, the telephone such as that it is no longer locked, to be unlocked.

The problem is in Android 4.3 to Android 5.1.1, which together more than half of all Android devices. According to researchers at Trend Micro appears to be the vulnerability this week announced Stage Fright leak . Both vulnerabilities arise due to the way Android handles media files, although the way these files reach different user. Google was on May 15 informed about the problem, but still has not rolled out updates.